๐บ๐ฆ
URAN Publishing Service
2026-10-01 13:29:55
(15 hours ago)
[01/Oct/2026:16:29:54 +0300] -- 104.23.166.144 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[01/Oct/2026:16:29:54 +0300] -- 104.23.166.144 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:18:55
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:18:52.603083 2026] [security2:error] [pid 8765:tid 8765] [client 104.23.166.144:14118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asiabeef.network"] [uri "/.git/HEAD"] [unique_id "ar5dvDfg1_OZgQ0ptrR77QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 10:22:18
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:22:12.277564 2026] [security2:error] [pid 29739:tid 29739] [client 104.23.166.144:11310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lisagilinger.com"] [uri "/.htaccess"] [unique_id "ar40VOqgjSbv4vmbuf3UzQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:53:57
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 104.23.166.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.166.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:53:50.545838 2026] [security2:error] [pid 4883:tid 4883] [client 104.23.166.144:9277] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jetzilla.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jetzilla.com"] [uri "/index.php.bak"] [unique_id "ar0GXou0DEnPs-Im4yqaWQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 07:29:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 03:29:43.748622 2026] [security2:error] [pid 12662:tid 12662] [client 104.23.166.144:13395] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "love-n-promises.com"] [uri "/.svn/entries"] [unique_id "ary6Z0xNyD6UW5DI-Vf97QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-09-30 05:15:34
(1 day ago)
Probing for .env file:
104.23.166.144 - - [30/Sep/2026:07:15:27 +0200] "GET /.env.production HTTP/2. ...
show more
Probing for .env file:
104.23.166.144 - - [30/Sep/2026:07:15:27 +0200] "GET /.env.production HTTP/2.0" 403 548 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
show less
Web App Attack
Anonymous
2026-09-30 05:10:13
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ญ๐บ
bcsaba
2026-09-30 01:45:56
(2 days ago)
Probing for .env file:
104.23.166.144 - - [30/Sep/2026:03:45:54 +0200] "GET /.env.staging HTTP/2.0" ...
show more
Probing for .env file:
104.23.166.144 - - [30/Sep/2026:03:45:54 +0200] "GET /.env.staging HTTP/2.0" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0"
show less
Web App Attack
๐ฆ๐บ
afleventoffice.com.au
2026-09-29 22:13:26
(2 days ago)
GET /.git/config HTTP/1.1
Web App Attack
๐ซ๐ท
dynamix
2026-09-29 20:55:27
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 20:08:43
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 104.23.166.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.166.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:08:40.557891 2026] [security2:error] [pid 12424:tid 12424] [client 104.23.166.144:12010] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tolenaar.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tolenaar.com"] [uri "/index.php.bak"] [unique_id "arwayF-WlgNJczAAo3IuogAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-29 15:35:15
(2 days ago)
[29/Sep/2026:18:35:14 +0300] -- 104.23.166.144 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[29/Sep/2026:18:35:14 +0300] -- 104.23.166.144 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 15:31:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 11:31:20.798235 2026] [security2:error] [pid 10274:tid 10292] [client 104.23.166.144:11435] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thomas.kiehnefamily.us"] [uri "/.svn/entries"] [unique_id "arvZyL2I-h9DjRcoB_8FEQAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 13:51:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 09:51:49.889319 2026] [security2:error] [pid 1614:tid 1614] [client 104.23.166.144:12373] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wildlifetaxidermy.com"] [uri "/.env.backup"] [unique_id "arvCdYR9rdd_Nhrob60VyAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 12:43:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 08:43:11.110439 2026] [security2:error] [pid 14996:tid 14996] [client 104.23.166.144:9229] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.appalachianstomp.com"] [uri "/.env.production"] [unique_id "aruyX0RDOcLHB6KfbTdKJAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack